Social engineering of a person
Pretexting
Pretexting is social engineering built on an invented story, the pretext, that gives the attacker a believable reason to ask for information or access. The attacker might pose as an auditor, new hire, vendor or the account holder. Each detail gathered makes the next request more convincing to the people being targeted.
How it works
The attacker picks a role the target expects to deal with and prepares supporting details, such as names, ticket numbers or account facts. They then make a request that fits the role, by phone, email or chat. Requests usually start small, and each answer is used to build credibility for a larger one.
A real example
In April 2001, as part of Operation Detect Pretext, the Federal Trade Commission sued to halt information brokers that used false pretenses, fraudulent statements or impersonation to obtain consumers' confidential financial information and sell it.
Source: As Part of "Operation Detect Pretext" FTC Sues to Halt "Pretexting" — Federal Trade Commission (FTC), 2001-04-18
The Identity Attack Ledger holds 12 cited incidents for social engineering of a person in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.
How to stop it
Set identity checks for account changes that do not rely on personal facts a caller could research, and give staff a standard way to verify a request through a separate, known channel.
Related terms
Threat actors that use it
- ALPHV Blackcat
Profile with government sources
- Black Basta
Profile with government sources
- Lazarus Group
Profile with government sources
- Scattered Spider
Profile with government sources
Sources
- As Part of "Operation Detect Pretext" FTC Sues to Halt "Pretexting" — Federal Trade Commission (FTC), 2001-04-18
Last reviewed Oct 2, 2026